Skip to content

Latest commit

 

History

History
236 lines (186 loc) · 12.7 KB

README.md

File metadata and controls

236 lines (186 loc) · 12.7 KB

Audit Experience

About vnmrtz

vnmrtz is an experienced security researcher and the Co-Founder and Lead Security Researcher at Enigma Dark, where they lead efforts in smart contract security for protocols such as Euler Finance, Aave, Silo Finance, Flower Money, and TapiocaDAO. vnmrtz specializes in smart contract auditing fuzz testing, and invariant testing, improving the security of decentralized EVM-based smart contract systems.

In addition to his work at Enigma Dark, vnmrtz serves as a Security Researcher at Spearbit and has contributed as a Smart Contract Auditor at Oak Security and Solidified, contributing to the security of complex and high-profile DeFi codebases.

With dedicated focus on fuzz testing and invariant research, vnmrtz has created the largest number of fuzzing suites developed by any security researcher. As a leading fuzzing expert, he has played a key role in advancing smart contract fuzz testing across the entire ecosystem. vnmrtz developed the Enigma Dark Invariant Framework and has collaborated with major protocols to design and implement over 10 customized testing suites that uncover edge cases and enhance protocol security.

Since beginning his white-hat journey in 2021, vnmrtz has uncovered and resolved critical vulnerabilities in leading protocols like AAVE and RAI, protecting over $33M in live assets.

vnmrtz Enigma Dark Fuzz / Invariant Testing Engagements

Euler Labs: EVK

  • Protocol: Euler v2, EVK
  • Description: The Euler Vault Kit (EVK) is the building block of Euler’s V2 ecosystem, enabling ERC-4626-based credit vaults with borrowing functionality and collateral-backed lending.
  • Links:

Euler Labs: Reward Streams

  • Protocol: Euler v2, Reward Streams
  • Description: Staking Rewards protocol for permissionless rewards distribution of multiple tokens in staking and staking-free manner.
  • Links:

Euler Labs: EVC Playground

Tapioca DAO: Bar

Tapioca DAO: Tap Token

  • Protocol: Tapioca DAO, Tap Token
  • Description: Token and option locking system of the Tapioca protocol.
  • Links:
    • Testing Suite: TBD

Aave: Aave v3 Protocol

  • Protocol: AAVE, v3.2-3.3
  • Description: The Aave Protocol is a decentralised non-custodial liquidity protocol where users can participate as suppliers, borrowers, or liquidators.
  • Links:
    • Report: TBD
    • Testing Suite: TBD

Silo: Silo v2 Core

  • Protocol: Silo v2, Core
  • Description: Silo is the main component of the Silo v2 protocol. It implements lending logic, manages and isolates risk, and acts as a vault for assets.
  • Links:

Euler Labs: Euler Earn

Flower Money: Core Contracts

  • Protocol: Flower Money, Core Contracts
  • Description: A Synthetic Stablecoin protocol built on top of Euler's v2 ecosystem.
  • Links:
    • Report: TBD
    • Testing Suite: TBD

vnmrtz Enigma Dark Security Reviews

BGD Labs: Aave v3.2 Protocol Upgrade

Flayer Labs: Flaunch

  • Protocol: Flaunch Protocol
  • Description: The ƒlaunch protocol is a launchpad platform built on Uniswap v4 hook system, incorporating advanced mechanics for token launch and trading.
  • Links:

Flayer Labs: Flaunch Upgrade

  • Protocol: Flaunch Protocol
  • Description: The ƒlaunch protocol is a launchpad platform built on Uniswap v4 hook system, incorporating advanced mechanics for token launch and trading.
  • Links:

Juicebox: Protocol v4

  • Protocol: Juicebox, Protocol v4
  • Description: Juicebox v4 is a protocol designed to manage token-based programmable treasuries for individuals and projects.
  • Links:

Asterix: Vaults

  • Protocol: Asterix, Vaults
  • Description: Asterix is a protocol focused on unlocking new possibilities of digital ownership, leveraging innovative standards such as the DN404 and ERC-6551.
  • Links:

Solady: ERC-6551

  • Protocol: Solady, ERC-6551
  • Description: Solady is a code library of hyper-optimized solidity snippets.
  • Links:

vnmrtz Spearbit Security Reviews

TBD

vnmrtz Cantina Security Reviews

TBD

vnmrtz Oak Security / Solidified Reviews

HAI: Stablecoin, RAI fork on Optimism

  • Protocol: HAI
  • Description: HAI is a stablecoin protocol that is backed by a variety of collaterals. It maintains its stability through the use of a PI controller which dynamically sets interest rates that affect the price of HAI.
  • Links:

Mauve: Mauve Protocol

  • Protocol: Mauve DEX
  • Description: Mauve is a Uniswap v3 fork, with additional KYC mechanics.
  • Links:

Mauve: Mauve Protocol

  • Protocol: Mauve DEX
  • Description: Mauve is a Uniswap v3 fork, with additional KYC mechanics.
  • Links:

Xaya: Democrit

  • Protocol: Xaya, Democrit
  • Description: Democrit is a protocol and system for executing atomic trades on the XAYA platform. This allows players to trade their game assets for cryptocurrency (CHI) in a fully trustless manner.
  • Links:

vnmrtz Bug Disclosures

July 2022

  • Protocol: [HIGH] AAVE v3 token, DeFi Lending and Borrowing
  • Link: Disclosure
  • Reflection: Found a high-severity issue on the AAVE token, fixed by the AAVE team.

October 2023

  • Protocol: [HIGH] RAI (debt auctions bug), non-pegged stable-coin
  • Link: Write-up
  • Reflection: Discovered a high-severity bug in RAI, leading to unintended overinflation.

November 2023

  • Protocol: [HIGH] TAI (debt auctions bug), stablecoin
  • Link: Private, Website
  • Reflection: Addressed the identified bug in the TAI Company.

December 2023

  • Protocol: [CRITICAL] RAI (liquidations DOS, GEB framework zero day), non-pegged stable-coin
  • Link: Disclosure
  • Reflection: Discovered a critical bug in the GEB framework of the RAI stablecoin, securing +33M of TVL at risk.

vnmrtz Formal Vefirication Reviews

Aave-token v3

  • Company: Certora, AAVE
  • Links:
  • Reflection: Identified a high-severity issue, won first place in AAVE grant.

Aave-starknet: bridge

  • Company: Certora, AAVE
  • Links:
  • Reflection: Implemented 18 formal rules, achieved sixth place in AAVE grant.

Blockswap Formal Verification

  • Company: Certora
  • Link: GitHub
  • Reflection: Implemented 10 formal rules for Syndicate codebase.

vnmrtz Miscellaneous Security Reviews

OpenDollar

  • Company: C4 contest
  • Description: Open Dollar is an Arbitrum-based CDP stablecoin platform based on the reflexer DEB framework.
  • Link: Contest Page
  • Reflection: Despite my usual focus on bug bounties and security reviews, I came across a high-severity issue identified only by another warden. This finding earned a spot in the official report and achieved a noteworthy sixth place in the contest rankings.

Sablier: v2-core & v2-periphery changelog audit

Unhosted Wallet:

  • Company: Independent Audit
  • Description: Unhosted is an Account Abstraction (AA) wallet that utilizes a series of smart contracts for trustless DeFi integrations.
  • Link: GitHub

exit10: boostraping

  • Company: yAcademy
  • Link: Report

VMEX: AAVE v2 fork

  • Company: yAcademy
  • Link: Report
  • Reflection: Found a unique high-severity issue.

Public Content

Talks and Seminars

Delivered talks and seminars on EVM, fuzzing and smart contract security:

Articles and Write-ups

Collection of articles on EVM and security, along with detailed write-ups of publicly disclosed bugs on blog: